Security Researcher & Tool Builder
把安全信号转化为可执行的检测、响应与工程化工具。
Turning security signals into practical detection, response, and engineering systems.
Offensive Security ·
Threat Detection ·
Incident Response ·
AI Automation
|
01 // 攻防与漏洞研究 面向授权场景的漏洞发现、验证与治理。 |
02 // 检测、研判与响应 从日志与流量中提取线索,形成可解释的安全结论。 |
03 // AI 安全自动化 用智能工作流缩短侦察、分析、处置与报告链路。 |
|
把内网评估命令与结果整理成清晰、可复用的工作流。 |
将原始 Web 日志转化为可解释的威胁研判结果。 |
|
面向公开泄露风险的发现、只读验证与持续监控。 |
用规则、威胁情报和攻击链视角完成结构化日志研判。 |
|
聚合多源情报,对 IP 与域名形成加权研判。 |
为失陷主机提供快速网络隔离与生效验证。 |
| Security Engineering | Detection & Response | Development | Platforms |
|---|---|---|---|
| 漏洞评估 授权测试 漏洞治理 |
日志与流量分析 威胁情报 应急响应 |
Python TypeScript LLM Agent |
Linux · Docker MySQL · Redis Security Toolchains |
| 2023 — Now | Security Engineering Practice — 安全运营、漏洞治理、日志分析与自动化工具开发。 |
| Recognition | National & Provincial — 企业信息安全、信息安全管理评估与 AI 信息素养相关赛事经历。 |
| Principle | Build for real workflows — 持续把侦察、检测、响应和报告沉淀为可复用工具链。 |
Metrics are generated daily from explicitly public repositories through the GitHub API and stored here. No private activity or third-party stats image service is used.
- 🚀 DarkForest-Hunter — pushed updates
- ⭐ Tencent/AI-Infra-Guard — starred this project
- ⭐ zhaoxuya520/reverse-skill — starred this project
欢迎围绕安全工具、威胁检测、应急响应与 AI 安全自动化交流协作。
Open to collaboration on practical security tooling, detection engineering, incident response, and AI-assisted security workflows.
All security research and tooling is intended for authorized testing, defensive research, and education.

